IBM JDK 7 SR10 FP50 (7.0.10.50), 7.1 SR4 FP50 (7.1.4.50), and 8 SR5 FP40 (8.0.5.40) fix a flaw described by upstream as: Eclipse OpenJ9 could allow a local attacker to gain elevated privileges on the system, caused by an error where the loop versioner fails to privatize a value that is pulled out of the loop by versioning. An attacker could exploit this vulnerability to corrupt memory and trigger an out-of-array-bounds and perform invalid actions. OpenJ9 upstream bug: https://bugs.eclipse.org/bugs/show_bug.cgi?id=549601 Eclipse OMR upstream bug and merge request: https://bugs.eclipse.org/bugs/show_bug.cgi?id=549192 https://github.com/eclipse/omr/pull/4138 References: https://www-01.ibm.com/support/docview.wss?uid=ibm10960422 https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBM_Security_Update_July_2019
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Supplementary Via RHSA-2019:2495 https://access.redhat.com/errata/RHSA-2019:2495
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Supplementary Via RHSA-2019:2494 https://access.redhat.com/errata/RHSA-2019:2494
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-11775
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Supplementary Via RHSA-2019:2585 https://access.redhat.com/errata/RHSA-2019:2585
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2019:2590 https://access.redhat.com/errata/RHSA-2019:2590
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Supplementary Via RHSA-2019:2592 https://access.redhat.com/errata/RHSA-2019:2592
This issue has been addressed in the following products: Red Hat Satellite 5.8 Via RHSA-2019:2737 https://access.redhat.com/errata/RHSA-2019:2737